MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 04b164050340a5ee03ceeea61915ba4a1aea309a38d1fda1d59e86929d616cc8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 04b164050340a5ee03ceeea61915ba4a1aea309a38d1fda1d59e86929d616cc8
SHA3-384 hash: 9800b9722f4706005f0d7468678ff4b2849def08f5ab21454f9227f164d821677bcd2963a38393159853c5f09c64e871
SHA1 hash: 5347aacbe7010224c7da312b54fd7f514db3ec0a
MD5 hash: 9d3c0137b2a1e55f5c27ab634de2796a
humanhash: tennis-lima-violet-april
File name:Product Specifications.lzh
Download: download sample
Signature GuLoader
File size:27'919 bytes
First seen:2020-05-25 12:58:12 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:OmOJK3Q+4WQpK/nP+8CMqp7e8nvBUs7gT2YhNiuTxc3si/KZQr:CJK3Q+8K/nP++F8vmscjqOk/KKr
TLSH 2CC2F1CBE8FC03C6421099317DBA3A8203B3DB107F144FA60714868D7FBDAB59675892
Reporter cocaman
Tags:GuLoader lzh


Avatar
cocaman
Malicious email
From: Cristina Spatura<info@aquichab.com>
Received: from slot0.aquichab.com (slot0.aquichab.com [45.95.169.120])
Date: 25 May 2020 05:23:31 -0700
Subject: Re: Send price
Attachment: Product Specifications.lzh

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-25 13:36:38 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
18 of 48 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 04b164050340a5ee03ceeea61915ba4a1aea309a38d1fda1d59e86929d616cc8

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments